4 ms·
bit.ly/ndt4ss What does it take to get some attention on HN? Do you have to be part of some secret cabal? I solved all the problems he talks about (and I worked
by cybernytrix 15y ago
bit.ly/ndt4ss
What does it take to get some attention on HN? Do you have to be part of some secret cabal? I solved all the problems he talks about (and I worked with a crypto guy):
- Statically encrypt and publish content on HTTP server
- Transmit these via HTTP to an iframe component at client browser
- HTTP-iframe locally sends message to HTTPS-iframe via window.postMessage()
- HTTPS-iframe decrypts content (with pre-shared key) and renders it on page
I implemented a library to do this (3 years ago!). Anyone care to tell me just ONE vulnerability with this? Thanks!
bit.ly/ndt4ss
- nbpoole 15y agoGot a demo set up somewhere?
- marshray 15y agoThe unencrypted (or more importantly, unauthenticated) content loading into the iframe is subject to any number of malicious content injection techniques. E.g. http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/ http://www.thespanner.co.uk/2007/10/24/iframes-security-summ... Professional malware distributors seem perfectly happy to obtain placement inside an iframe: http://www.usenix.org/event/hotbots07/tech/full_papers/provos/provos.pdf http://www.usenix.org/event/hotbots07/tech/full_papers/provo... Edit: Also, don't you trigger mixed content warnings in the browser?